• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Exclusive

An hour in the Oval Office with President Trump.

An hour in the Oval Office with President Trump.

An hour in the Oval Office with President Trump.

An hour in the Oval Office with President Trump.

An hour in the Oval Office with President Trump.

An hour in the Oval Office with President Trump.

An hour in the Oval Office with President Trump.

An hour in the Oval Office with President Trump.

An hour in the Oval Office with President Trump.

An hour in the Oval Office with President Trump.

TechGoogle

Google Fixes Ultra Sneaky Gmail Phishing Trick

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
February 27, 2017, 8:10 PM ET

Google has countered a “highly effective” phishing scam that in recent months impacted users of its Gmail email service.

Scammers had been tricking people into divulging their passwords by directing them to lookalike login pages that tripped no alarms in the victim’s web browser. Security researchers at WordFence, a company that makes security tools for WordPress sites, last month warned that the phishing effort was “having a wide impact, even on experienced technical users.”

No longer. Google has responded to the problem with an update to its Chrome browser. In the new version, released earlier this month, the browser’s address bar warns people when they have been served a page that uses the phishing trick.

Get Data Sheet, Fortune’s technology newsletter.

While the browser previously indicated nothing suspicious about the sham account sign-ins, the revamped version now displays “not secure” in such instances. (It is still incumbent upon the Gmail user to heed that warning, of course.)

Scammers had been sending people fraudulent email messages from the compromised accounts of known contacts. Inside, the notes included embedded images designed to look like PDF attachments that, when clicked, opened bogus Gmail login pages.

https://twitter.com/tomscott/status/812265182646927361

On the fake login pages, everything would look perfectly normal, except for a bit of unusual text, “data:text/html,” preceding the usual “https://.”

The scammers had been exploiting a distinction between a URL and the less common “data URI.” The former, more familiarly known as a web address, points to a page’s location on the web, accesses it, and lets people interact with it; a “data URI,” on the other hand, embeds a file.

In this case, the data URI ran a hidden program the served up phishing pages. Because Google Chrome failed to flag these pages as potentially dangerous, many people did not realize the hazard of entering their username and passwords—which the attackers would promptly nab, and then use to hijack more accounts.

Emily Schechter, a security product manager for Google Chrome, acknowledged the phishing scheme in a statement provided to Fortune on Monday. In it, she explained the company’s fix and hinted at stronger countermeasures to come.

The address bar in Chrome and other browsers helps users to determine a page’s identity. If the address, the URL, corresponds accurately to the page content, users feel confident they’re in the right place. Scammers might take advantage of that trust, and display pages that look like familiar sites, but have slightly different URLs. Sometimes these addresses start with “data:”; this was the case in the scam we saw recently. “Data:” addresses have some legitimate use cases, but in this case were used to purposely confuse users. Now, Chrome shows a “Not secure” label next to addresses that begin with “data:”, and we’ll be taking further action in upcoming versions of Chrome.

Alluding to that “further action,” a Google spokesperson said that Google has plans to prevent redirections to “data” sites entirely in future versions of the browser, “so the action will be even more aggressive fairly soon.”

For now, Chrome’s in-browser warning reads “not secure” alongside a gray circle, as pictured below. (Eventually, the company plans to place a more flamboyant red triangle in the browser bar for all sites not fully protected by “https.”)

screen-shot-2017-02-27-at-6-57-37-pm

Mark Maunder, CEO of WordFence and who first raised the phishing scam to Fortune’s attention in a blog post last month, said he was satisfied with Google’s remedy. “Chrome has resolved this issue to my satisfaction,” he wrote Friday in an update.

In sum: make sure, if you use Chrome, that your browser is up to date. Steer clear of “not secure” web pages (in addition to ones not protected by “https”) when entering credentials. And always triple check to make sure you’re transacting with the intended website before entering a password.

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

murdochs
CommentaryMedia
OpenAI paid $100 million for a talk show. James Murdoch is eyeing an even bigger deal. The hot new asset class is humanity
By Lin CherryMay 17, 2026
17 hours ago
dennis
CommentaryAI agents
Freshworks CEO: why agile enterprises are winning the AI race — and what they did differently
By Dennis WoodsideMay 17, 2026
17 hours ago
A man with a headset sits at a desk in a call center.
EconomyAutomation
The AI boom hasn’t stopped U.S. companies from hiring cheap offshore labor, and overseas call center employment is still skyrocketing
By Sasha RogelbergMay 17, 2026
18 hours ago
Zillow CEO doubles down on remote-work model: ‘There is talent everywhere in this country’
Workplace Cultureremote work
Zillow CEO doubles down on remote-work model: ‘There is talent everywhere in this country’
By Marco Quiroz-GutierrezMay 17, 2026
18 hours ago
Stressed job seeker
SuccessGen Z
Gen Z is right about the job hunt—it really is worse than it was for millennials, with nearly 60% of fresh-faced grads frozen out of the workforce
By Emma BurleighMay 17, 2026
18 hours ago
A 45,000-person labor strike at Samsung’s memory chip plants could throw a wrench into the AI boom
EconomySamsung
A 45,000-person labor strike at Samsung’s memory chip plants could throw a wrench into the AI boom
By Catherina GioinoMay 17, 2026
21 hours ago

Most Popular

Microsoft AI chief gives it 18 months—for all white-collar work to be automated by AI
AI
Microsoft AI chief gives it 18 months—for all white-collar work to be automated by AI
By Jake AngeloMay 16, 2026
2 days ago
The Bezos family just donated $100 million to help achieve one of Mayor Zohran Mamdani’s top campaign promises
Politics
The Bezos family just donated $100 million to help achieve one of Mayor Zohran Mamdani’s top campaign promises
By Jake AngeloMay 12, 2026
5 days ago
The top foreign holders of U.S. debt may soon dump Treasury bonds and bring their money back home, potentially spiking borrowing costs
Economy
The top foreign holders of U.S. debt may soon dump Treasury bonds and bring their money back home, potentially spiking borrowing costs
By Jason MaMay 17, 2026
12 hours ago
'No one was coming to save me': How Reese Witherspoon built a $900 million company from a problem Hollywood wouldn't fix
Success
'No one was coming to save me': How Reese Witherspoon built a $900 million company from a problem Hollywood wouldn't fix
By Sydney LakeMay 17, 2026
19 hours ago
Former top Russian official admits the country is over Putin and can 'imagine a future without him' — even elites bail as Kremlin seizes their assets 
Politics
Former top Russian official admits the country is over Putin and can 'imagine a future without him' — even elites bail as Kremlin seizes their assets 
By Jason MaMay 16, 2026
1 day ago
SpaceX heads into a record-shattering IPO with the 'deepest moat that exists today' as investors vow to 'never bet against Elon'
Innovation
SpaceX heads into a record-shattering IPO with the 'deepest moat that exists today' as investors vow to 'never bet against Elon'
By Jason MaMay 16, 2026
2 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.